Security Cryptography Whatever cover image

Threema with Kenny Paterson, Matteo Scarlata and Kien Tuong Truong

Security Cryptography Whatever

00:00

ATT&CK2 Attack

ATT&CK2 is able to register the servers' public key as a user's public key by tricking the victim into sending a carefully crafted message in the ETE protocol and enables it to permanently impersonate the victim. This is a fun cross-particle attack between the C2S, aka the TLS-like client to server protocol and the actual end-to-end encrypted messaging protocol underneath it. The idea is that whenever you receive a message, if there is a metadata box, the values contained within the metadata box will overwrite the values outside.

Transcript
Play full episode

Remember Everything You Learn from Podcasts

Save insights instantly, chat with episodes, and build lasting knowledge - all powered by AI.
App store bannerPlay store banner
Get the app